← Back to Daily Briefing (#DeFi)

A large-scale exfiltration campaign has targeted Azure/Entra ID tenants across multiple Fortune 500 organizations, resulting in the leakage of millions of internal employee records. The threat actor, identified as 'TheHatman,' utilized compromised credentials—likely obtained via Infostealer-driven session token theft—to access corporate directories through Azure/Entra portals and the Azure CLI. Exfiltrated datasets comprise core identities, detailed organizational metadata, and sensitive access control information, including service account listings and Global Administrator records. This breach provides high-value intelligence that significantly facilitates downstream high-impact attacks, such as Business Email Compromise (BEC), advanced spear-phishing, and ransomware deployment through lateral movement and privilege escalation.

  • Incident Overview & Scale
    • Large-scale exfiltration of millions of internal records from global Fortune 500 entities.
    • Major organizations impacted include McDonalds (~1.7M records), TCS (~800k), Vodafone (~425k), HCL Technologies (~250k), and Kyndryl (~170k).
    • Affected sectors span IT Services, Telecommunications, Hospitality, Retail, and Logistics.
  • Attack Vector & Technical Mechanics
    • Primary entry vector: Likely Infostealer-facilitated session token theft and credential harvesting.
    • Observed/Potential vectors: Azure CLI password spraying and exploitation of administrative accounts lacking robust Multi-Factor Authentication (MFA).
    • Targeted infrastructure: Microsoft Azure/Entra ID identity management environments.
  • Scope of Exfiltrated Data
    • Core Identity: Full names, UserPrincipalNames, corporate emails (including .onmicrosoft.com domains), phone numbers, and physical addresses.
    • Organizational Metadata: Employee IDs, job titles, department mappings, and manager/direct report hierarchies.
    • Access Control Intelligence: User group memberships, service account inventories, and high-privilege Global Administrator records.
  • Threat Actor Profile & Strategic Impact
    • Threat actor 'TheHatman' is actively advertising these stolen directories on cybercrime forums for monetization.
    • Target selection of Global Administrators and service accounts provides a blueprint for targeted privilege escalation.
    • Stolen data serves as critical reconnaissance for sophisticated Business Email Compromise (BEC) and ransomware campaigns.
  • Defensive Mitigation Strategies
    • Deploy phishing-resistant MFA (FIDO2/WebAuthn) to mitigate session hijacking and credential-based access.
    • Enforce strict Conditional Access policies to restrict Azure CLI and Entra portal access to managed, compliant devices.
    • Increase monitoring for anomalous identity enumeration and unauthorized Azure CLI activity within Entra ID.
    • Conduct immediate audits of service account permissions and high-privilege administrative role assignments.

Related posts

  1. Malware News — Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records via Compromised Credentials (Mcdonald’s, Vodafone, Kyndryl & Others)
  2. Infostealers
  3. Thehackernews
  4. Securityweek
  5. Securityboulevard
  6. Microsoft
  7. Reddit
  8. Marketplace
  9. Learn

LINK COPIED TO CLIPBOARD